CWE-639: CWE-639

519
Total CVEs
63
Critical
165
High
6.6
Avg CVSS

Yearly Trend

2026
89
2025
239
2024
130
2023
28
2022
16

Top Affected Vendors

1 Growatt 12
2 Nextcloud 10
3 Easyappointments 8
4 Liferay 8
5 Boldworkplanner 8
6 Lunary 6
7 Gitlab 6
8 Open Emr 5
9 Wpjobportal 5
10 Apache 4

All CWE-639 CVEs (519)

CVE-2025-10912
5.4

This vulnerability allows attackers to bypass authorization controls in Saastech Cleaning and Internet Services Inc.'s TemizlikYolda software by manip...

Feb 11, 2026
CVE-2026-25574
5.4

This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in Payload CMS where authenticated users from one authentication collectio...

Feb 6, 2026
CVE-2026-1251
5.4

This vulnerability in the SupportCandy WordPress plugin allows authenticated attackers with subscriber-level access or higher to steal file attachment...

Jan 31, 2026
CVE-2026-22411
5.4

This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in the Mikado-Themes Dolcino WordPress theme. Attackers can bypass authori...

Jan 22, 2026
CVE-2026-22426
5.4

This vulnerability allows attackers to bypass authorization controls in the Sweet Jane WordPress theme by manipulating user-controlled keys, enabling ...

Jan 22, 2026
CVE-2026-22430
5.4

This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in the Mikado-Themes Verdure WordPress theme. Attackers can bypass authori...

Jan 22, 2026
CVE-2026-22398
5.4

This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in the Mikado-Themes Fleur WordPress theme. It allows attackers to bypass ...

Jan 22, 2026
CVE-2026-22400
5.4

This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in the Holmes WordPress theme that allows attackers to bypass authorizatio...

Jan 22, 2026
CVE-2026-22404
5.4

This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in the Mikado-Themes Innovio WordPress theme. Attackers can bypass authori...

Jan 22, 2026
CVE-2026-22406
5.4

This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in the Overton WordPress theme by Mikado-Themes. It allows authenticated u...

Jan 22, 2026
CVE-2026-22407
5.4

This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in the Mikado-Themes Roam WordPress theme. Attackers can bypass authorizat...

Jan 22, 2026
CVE-2026-22409
5.4

This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in the Justicia WordPress theme by Mikado-Themes. It allows attackers to b...

Jan 22, 2026
CVE-2026-22391
5.4

This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in the Mikado-Themes Cocco WordPress theme that allows attackers to bypass...

Jan 22, 2026
CVE-2026-22393
5.4

This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in the Curly WordPress theme by Mikado-Themes. Attackers can bypass author...

Jan 22, 2026
CVE-2026-22396
5.4

This vulnerability allows attackers to bypass authorization controls in the Fiorello WordPress theme by manipulating user-controlled keys, potentially...

Jan 22, 2026
CVE-2025-14802
5.4

This vulnerability in the LearnPress WordPress plugin allows authenticated attackers with teacher-level access to delete arbitrary lesson material fil...

Jan 7, 2026
CVE-2025-69029
5.4

This CVE describes an authorization bypass vulnerability in the Struktur WordPress theme, allowing attackers to access unauthorized data by manipulati...

Dec 30, 2025
CVE-2025-69030
5.4

This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in the Backpack Traveler WordPress theme that allows attackers to bypass a...

Dec 30, 2025
CVE-2025-69032
5.4

This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in the Mikado-Themes FiveStar WordPress theme. Attackers can bypass author...

Dec 30, 2025
CVE-2025-12881
5.4

This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to read other users' order messages through the Return ...

Nov 21, 2025
CVE-2025-12524
5.4

The Post Type Switcher WordPress plugin up to version 4.0.0 has an Insecure Direct Object Reference vulnerability that allows authenticated attackers ...

Nov 18, 2025
CVE-2025-63291
5.4

This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in Alteryx Server where authenticated users can access other users' data b...

Nov 14, 2025
CVE-2025-57994
5.4

This CVE describes an authorization bypass vulnerability in the Upcoming Events Lists WordPress plugin where attackers can manipulate object reference...

Sep 22, 2025
CVE-2025-57886
5.4

This vulnerability allows attackers to bypass authorization controls by manipulating user-controlled keys, potentially accessing unauthorized data or ...

Aug 22, 2025
CVE-2025-53357
5.4

This vulnerability in GLPI allows authenticated users to modify other users' reservations, potentially disrupting IT asset management and service desk...

Jul 30, 2025
CVE-2025-31867
5.4

This vulnerability allows attackers to bypass authorization controls in JoomSky JS Job Manager by manipulating user-controlled keys, potentially acces...

Apr 1, 2025
CVE-2024-45614
5.4

This vulnerability in Puma web server allows clients to override proxy-set headers like X-Forwarded-For by sending underscore versions (X-Forwarded_Fo...

Sep 19, 2024
CVE-2024-8123
5.4

This vulnerability in the WP Extended WordPress plugin allows authenticated attackers with Contributor-level access or higher to duplicate posts creat...

Sep 4, 2024
CVE-2024-31898
5.4

This vulnerability in IBM InfoSphere Information Server 11.7 allows authenticated users to bypass authorization controls and access or modify sensitiv...

Jun 30, 2024
CVE-2024-2346
5.4

This vulnerability in the FileBird WordPress plugin allows authenticated attackers with author-level access or higher to delete folders created by oth...

May 2, 2024
CVE-2026-1219
5.3

This vulnerability allows unauthenticated attackers to view private WordPress posts by exploiting an insecure direct object reference in the MP3 Audio...

Feb 19, 2026
CVE-2026-25324
5.3

This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in the Quiz And Survey Master WordPress plugin that allows attackers to by...

Feb 19, 2026
CVE-2026-25005
5.3

This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in the N-Media Frontend File Manager WordPress plugin. It allows attackers...

Feb 19, 2026
CVE-2026-25757
5.3

Unauthenticated users can view completed guest orders by Order ID in Spree e-commerce platform, potentially exposing guest user PII including names, a...

Feb 6, 2026
CVE-2026-1271
5.3

This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to change any user's profile picture or cover image, in...

Feb 5, 2026
CVE-2026-24991
5.3

This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in the Extensions For CF7 WordPress plugin. It allows attackers to bypass ...

Feb 3, 2026
CVE-2026-0909
5.3

The WP ULike WordPress plugin has an Insecure Direct Object Reference vulnerability that allows authenticated attackers with Subscriber-level access o...

Feb 3, 2026
CVE-2026-1389
5.3

This vulnerability allows authenticated WordPress users with Author-level permissions or higher to access, modify, and delete Document Library entries...

Jan 28, 2026
CVE-2025-49334
5.3

This vulnerability allows attackers to bypass authorization controls in the MyD Delivery WordPress plugin by manipulating user-controlled keys, potent...

Dec 31, 2025
CVE-2025-63053
5.3

This vulnerability allows attackers to bypass authorization controls in the Jewel Theme Master Addons for Elementor WordPress plugin by manipulating u...

Dec 31, 2025
CVE-2025-68997
5.3

This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in the wpDiscuz WordPress plugin that allows attackers to bypass authoriza...

Dec 30, 2025
CVE-2025-63043
5.3

This vulnerability allows attackers to bypass authorization controls in the PickPlugins Post Grid and Gutenberg Blocks WordPress plugin by manipulatin...

Dec 18, 2025
CVE-2025-67985
5.3

This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in Barn2 Plugins Document Library Lite WordPress plugin. Attackers can byp...

Dec 16, 2025
CVE-2025-12883
5.3

The Campay Woocommerce Payment Gateway plugin for WordPress has a vulnerability that allows unauthenticated attackers to bypass payment processing and...

Dec 12, 2025
CVE-2025-63065
5.3

This vulnerability allows attackers to bypass authorization controls in the Media Library Assistant WordPress plugin by manipulating user-controlled k...

Dec 9, 2025
CVE-2025-13157
5.3

The QODE Wishlist for WooCommerce WordPress plugin has an Insecure Direct Object Reference vulnerability that allows unauthenticated attackers to modi...

Nov 27, 2025
CVE-2025-13389
5.3

The WooCommerce OrderConvo plugin has an authorization bypass vulnerability that allows unauthenticated attackers to view sensitive order details and ...

Nov 25, 2025
CVE-2025-12427
5.3

The YITH WooCommerce Wishlist plugin for WordPress has an Insecure Direct Object Reference vulnerability that allows unauthenticated attackers to disc...

Nov 19, 2025
CVE-2025-11532
5.3

The Wisly WordPress plugin has an Insecure Direct Object Reference vulnerability that allows unauthenticated attackers to manipulate other users' wish...

Nov 11, 2025
CVE-2025-12353
5.3

The WPFunnels WordPress plugin has an authorization bypass vulnerability that allows unauthenticated attackers to register user accounts even when sit...

Nov 8, 2025

About CWE-639 (CWE-639)

Our database tracks 519 CVEs classified as CWE-639, with 63 rated critical and 165 rated high severity. The average CVSS score for CWE-639 vulnerabilities is 6.6.

External reference: View CWE-639 on MITRE CWE →

Monitor CWE-639 Vulnerabilities

Get alerted when new CWE-639 CVEs affect your infrastructure.

Start Monitoring Free